Privacy policy
We collect the minimum needed to answer your enquiry, we do not sell it, and we delete it when you ask us to. The detail is below.
- Last updated
- 27 July 2026
- Applies to
- arb-zone.com
- Questions
- hello@arb-zone.com
Who we are
ARB-ZONE(“ARB-ZONE”, “we”, “us”) is a product engineering and cybersecurity studio. We are the data controller for information submitted through this website.
Post: 7901 4th St N, 34590, St Petersburg, FL 33702, United States
Email: hello@arb-zone.com
Phone: +1 (201) 564-0119
What we collect
Information you give us
When you submit the contact form or a project brief, we receive whatever you enter into it. Depending on the form, that can include:
- Your name, work email address, phone number and job role
- Your company name, website, size and location
- The services you are interested in, and details of the project or problem
- Budget band, timeline, deadlines and compliance requirements
- Your message, and any files you choose to attach
- Your preferred contact method and best time to be reached
Only a handful of fields are required. Anything marked optional can be left blank without affecting our reply.
Information collected automatically
Our servers record the IP address and browser user-agent string attached to a form submission. We use this for two narrow purposes: rate-limiting the endpoints so they cannot be abused, and investigating abuse if it happens. We do not build behavioural profiles from it.
Files you upload
Attachments go to the engineer reviewing your enquiry and nowhere else. We accept documents, text, images and archives only, capped at 10 MB per file and 25 MB per submission.
Please do not upload production credentials, personal data belonging to your customers, or material you are not authorised to share. If you need to send something sensitive, say so in your message and we will arrange an encrypted channel instead.
Why we hold it
We process this information in order to:
- Reply to your enquiry and answer your questions
- Prepare an estimate, proposal or rules-of-engagement document
- Keep a record of what was discussed and agreed
- Protect the site and our systems from abuse
Where the GDPR or UK GDPR applies, our lawful bases are your consent (given when you tick the confirmation box on a form) and our legitimate interests in responding to business enquiries and securing our own infrastructure. Where US state privacy laws apply, we act as a business processing information you provided directly for the purpose you provided it.
Who else sees it
We do not sell your information, rent it, or share it with advertisers. We never trade personal data for money or for anything else of value.
A small number of service providers process it on our behalf, under contract:
- Hosting and content delivery — serves this website and runs the form endpoints
- Transactional email — delivers your submission to our inbox
- Business email and document storage — where our correspondence with you lives
We may also disclose information where we are legally required to, or where it is necessary to establish or defend a legal claim.
How long we keep it
- Enquiries that do not become projects: up to 24 months, then deleted
- Attachments: deleted once the estimate or proposal is complete, unless the project proceeds
- Project correspondence: retained for the life of the engagement plus the period required for tax and contractual records
- Request logs: retained briefly for abuse prevention, then rotated out
You can ask us to delete your enquiry sooner at any point, and we will, unless we are required to keep a record of it.
Cookies and analytics
This site sets no tracking cookies and runs no third-party advertising or analytics scripts. There is no cookie banner because there is nothing to consent to. Fonts are self-hosted, so loading a page does not call out to a font provider.
If we add privacy-respecting analytics in future, this section will be updated before it goes live, and anything requiring consent will ask for it first.
How we protect it
- All traffic to this site is encrypted in transit over TLS
- Form endpoints are rate-limited and validate every field on the server
- Uploads are restricted to an allow-list of document, text, image and archive types
- Access to submissions is limited to the people who need it to reply to you
- Multi-factor authentication is required on the accounts that hold this data
No system is perfect. If you believe you have found a vulnerability in this site, please contact us — see the responsible disclosure section of our terms of service.
Your rights
Depending on where you live, you may have the right to:
- Ask what personal information we hold about you, and get a copy
- Have inaccurate information corrected
- Have your information deleted
- Object to or restrict how we process it
- Withdraw consent at any time
- Not be discriminated against for exercising any of these rights
Email hello@arb-zone.comwith the word “privacy” in the subject line. We will respond within 30 days, and we will not ask you to justify the request. If you are in the EU or UK and are unhappy with our response, you may complain to your national data protection authority.
Changes
If this policy changes, the date at the top of the page changes with it. Material changes affecting how we handle information already submitted will be communicated to the people concerned rather than only posted here.
Last updated: 27 July 2026. This policy describes our actual practice. It has been written in plain language rather than by a law firm, so have your own counsel review it against your obligations before relying on it commercially.